GNOME's Wi-Fi panel has this and it is the most-used thing in it: the alternative is reading a passphrase out loud. Network & Devices now shows a scannable code for any saved network whose passphrase this user can read. The image contains the network password in machine-readable form, so most of the care here is about that rather than about QR codes. It is written under XDG_RUNTIME_DIR -- 0700, on tmpfs, gone at logout -- rather than /tmp, which is shared; the file is 0600; the passphrase is piped to qrencode on stdin rather than passed as an argument, because argv is world-readable through /proc for as long as the process runs; and it is never printed or included in an error message. Generated on demand, because producing a code for every saved network up front means writing images of passwords nobody asked to see. Enterprise networks are listed as not shareable rather than offered and broken: there is no passphrase to encode, so the code could not work. Two bugs the contract caught while being written. Semicolons in an SSID were not escaped -- the sed replacement had one backslash where its four neighbours have two, so sed dropped it, and an SSID containing a semicolon would have produced a QR code describing a different network. And nmcli's trailing newline landed inside the payload; it decoded here, but a newline in the middle of a WIFI: URI is not something every phone tolerates, and that failure would present as "the QR code just doesn't work on my phone". The contract stubs nmcli and qrencode, because the real ones would write this machine's actual Wi-Fi password into a fixture directory. It asserts the escaping, the absence of a newline, the file and directory modes, that no temporary payload survives, and that the passphrase never reaches argv. Claude-Session: https://claude.ai/code/session_01BRvzt4H8XXLPVH5MyYdk9L
Panama
Formerly Sunhat. A personal config for Fedora, with the intention of helping a user set up their Fedora system with one command.
git clone https://git.gbrown.org/gib/Panama.git ~/.local/share/Panama
~/.local/share/Panama/install
install runs everything in setup/scripts/ in order:
| Script | Does |
|---|---|
install-packages |
Repos (RPM Fusion, Terra, Hyprland COPR), then the four package lists in setup/packages/ |
link-dotfiles |
Symlinks config/dot/<name> → ~/.config/<name> |
change-settings |
Copies config/copy/ over /, applies gsettings, enables user services |
Existing configs are moved to config/old/ rather than overwritten.
Desktops
Panama configures two desktops that coexist. Both sessions stay available in GDM, so you can switch back and forth while you settle in.
GNOME
The original setup: Forge for tiling, Dash-to-Dock, Openbar, Vitals,
AppIndicator support. Configured through config/dot/forge/ and gsettings.
Hyprland
A from-scratch replacement built to reproduce the GNOME setup closely enough that muscle memory transfers — same keybinds, same panel contents, same dock, same Tokyo Night Moon palette.
| Piece | What it is |
|---|---|
config/dot/hypr/ |
Compositor config. Lua, not hyprlang — see its README |
config/dot/quickshell/ |
The shell: bar, dock, Continuum overview, Settings, Screen Intelligence, focus sessions, quick settings, notifications, screenshot UI |
config/dot/vicinae/ |
Raycast-style launcher, themed |
config/dot/uwsm/ |
Session environment (see the uwsm caveat in the hypr README) |
config/dot/wofi/ |
Fallback launcher, in case the shell fails to start |
config/dot/xdg-desktop-portal/ |
Portal backend routing |
Start here: config/dot/hypr/README.md — it
covers the Lua migration, the uwsm environment gotcha, the HDR decision, the
full keymap, and troubleshooting.
Log in as "Hyprland (uwsm-managed)", not plain "Hyprland".
Layout
bin/ Small user-facing commands on PATH
config/
bash/ .bashrc, aliases, env (env is gitignored)
copy/ Files copied verbatim over / (needs sudo)
dot/ Symlinked into ~/.config
old/ Backups of whatever was replaced (gitignored)
setup/
packages/ One package per line
scripts/ Run in order by ./install